July Patch Tuesday Unveils 137 Vulnerabilities: What You Need to Know

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Microsoft Security Updates: Key Vulnerabilities and Patches

Microsoft has acknowledged a recently disclosed vulnerability, but there are no reports of it being exploited in the wild. This acknowledgment comes as part of the Patch Tuesday updates on July 8, marking the tenth consecutive month without any zero-day vulnerabilities reported as critical at the time of their publication. This month’s patch round includes 11 critical remote code execution (RCE) vulnerabilities, although three browser vulnerabilities released earlier in the month are not part of this total.

Recent SQL Server Vulnerabilities and Patches

It’s been a relatively quiet period regarding SQL Server updates, but Microsoft recently released a patch for CVE-2025-49719. This is an information disclosure vulnerability that affects all SQL Server versions back to 2016. Microsoft classifies this vulnerability as important rather than critical. Notably, older SQL Server versions that qualify for the Extended Security Update (ESU) program are not receiving patches. The advisory bluntly indicates that any version not listed is no longer supported, suggesting that organizations using unlisted versions should take immediate action. For those with ESU subscriptions, there’s hope that today’s vulnerabilities stem from the SQL Server 2016 codebase.

Interestingly, the advisory notes that CVE-2025-49719 has been publicly disclosed, with a Microsoft researcher credited for reporting it. This suggests that Microsoft is aware of additional public information about the vulnerability. True to form, SQL Server security advisories typically provide extensive FAQs to help administrators navigate various SQL Server versions. However, they often gloss over the specifics of the vulnerabilities themselves. The potential consequences of a successful exploit include the exposure of uninitialized memory, which might not yield valuable information immediately but could, in theory, lead to the compromise of sensitive data like cryptographic keys.

Critical Remote Code Execution (RCE) Vulnerabilities

Among the critical vulnerabilities released this month is CVE-2025-47981, which presents an RCE risk within the way Windows clients and servers negotiate authentication mechanisms. This flaw is tied to the Simple and Protected GSS-API Negotiation Mechanism (SPNEGO), which includes an extension developed by Microsoft known as NEGOX. The advisory clarifies that the vulnerability impacts any Windows client machine running Windows 10 version 1607 or later.

Patches are available for all current Windows Server versions; however, immediate exploitation of these servers may be limited. This limitation primarily stems from the group policy setting that allows certain authentication requests, which is generally only enabled on client machines. Domain-joined client assets might also have similar mitigation strategies in place since the applicable group policy is often disabled in that context. Regardless, patching all Windows assets is recommended due to the pre-authentication RCE risk, especially within privileged environments where exploitation is deemed more likely.

Comparison with Previous Vulnerabilities

For those familiar with Windows KDC Proxy servers, CVE-2025-49735 may resonate as it shares similarities with last month’s CVE-2025-33071. This unauthenticated critical RCE vulnerability underscores the continuous security challenges facing Windows environments.

Furthermore, SharePoint administrators should take note of CVE-2025-49704, which allows attackers with some existing SharePoint privileges to remotely execute code on the SharePoint server. The advisory indicates that elevated privileges are not technically required for exploitation, yet it mentions that the minimum privilege level is a site owner. This complexity suggests an inconsistency worth investigating, and, given the low difficulty of exploitation, immediate patching is advised.

End of Support for SQL Server 2012

In product lifecycle news, the ESU program for SQL Server 2012 has officially concluded, which means no future security patches will be available for this version, even for critical vulnerabilities. While Microsoft sometimes releases updates for obsolete products addressing severe vulnerabilities, relying on this practice is not a sound security strategy. The Visual Studio 2022 17.8 LTSC channel is also reaching its end, though newer LTSC versions are still available.

At present, Microsoft has retracted all the security advisories initially released in June 2025. This appears to be an inadvertent act, and it’s anticipated that these advisories will be restored in the near future.

With numerous vulnerabilities highlighted, it’s crucial for organizations to stay updated and proactive in implementing these patches to ensure their systems remain secure.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

NovaCookies Phishing Toolkit Exploits Docusign Notifications to Hijack Microsoft 365 Sessions

Cybersecurity researchers have unveiled a new adversary-in-the-middle (AitM) phishing toolkit named NovaCookies, which is designed to redirect Microsoft 365 sign-ins while capturing authenticated sessions....

Cybercriminals Leak Grand Theft Auto VI Footage, Prompting Legal Action from Take-Two Interactive

Grand Theft Auto VI, anticipated as the game event of the decade, faced a major setback last week when a cybercriminal leaked gameplay footage...

Cybersecurity Patch Window Collapses, Urging New Control Strategies for Risk Management

For decades, cybersecurity defenders have relied on a straightforward model: when a vulnerability is disclosed, security teams assess exposure, test fixes, deploy patches, and...

Tehran-linked hackers shut down UK power plant in recent cyber attack

A recent cyber attack attributed to hackers linked to the Iranian regime has resulted in the shutdown of a small power plant in the...